PT-2010-4294 · Apache+1 · Apache Http Server+1

Published

2010-07-23

·

Updated

2023-02-13

·

CVE-2010-2791

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server version 2.2.9
Description The issue is related to an information disclosure flaw in the mod proxy component of the Apache HTTP Server. When running on Unix platforms, if a timeout occurs while reading a response from a persistent connection, the backend connection is not closed. This allows remote attackers to potentially obtain sensitive responses intended for other clients under certain circumstances. The flaw is triggered by specific timeout conditions and affects configurations that use proxy worker pools.
Recommendations For Apache HTTP Server version 2.2.9, as a temporary workaround, consider globally configuring the server with the setting: SetEnv proxy-nokeepalive 1. This configuration change can help mitigate the risk of information disclosure until a more permanent fix is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2791
RHSA-2010:0659
RHSA-2010_0659

Affected Products

Apache Http Server
Red Hat